New HHS-OIG Exclusions and Financial Penalties
Before hiring any individual or onboarding a new vendor, healthcare organizations that participate in federal healthcare programs such as Medicare or Medicaid must complete due diligence and check to ensure that the individual or entity is not excluded from participating in federally funded healthcare programs.
The Department of Health and Human Services Office of Inspector General (HHS-OIG) maintains an exclusions list consisting of individuals and entities that have been prohibited from participating in federal healthcare programs. Individuals and entities are added to the List of Excluded Individuals and Entities (LEIE) after being found guilty of fraud, abuse, or neglect, although they may be added to the list for other reasons at the discretion of HHS-OIG.
Failure to check the LEIE and subsequently billing federal healthcare programs for products or services provided by an excluded individual or entity can result in a significant fine. In addition to pre-engagement checks of the database, healthcare organizations must conduct regular checks of the LEIE for existing employees, contractors, and vendors. All checks must be documented to maintain an audit trail.
Free Webinar on Sanctions and Exclusions Compliance
Readers of the HIPAA Journal are invited to attend a free webinar, where they will be able to hear from leading compliance experts who will give their expert advice about implementing and maintaining an effective screening program that goes beyond the basic requirements to include establishing and managing conflict of interest programs.
The webinar – The Complete Exclusion Screening Playbook: From Sanctions to Conflicts of Interest – will take place on Tuesday, September 9, 2025. You can find out more and register for the event here.
Recent LEIE additions and Financial Penalties
HHS-OIG has recently announced four new additions to the LEIE, and one financial penalty for a healthcare provider for employing an excluded individual and billing federal healthcare programs for products or services provided by that individual.
- Kidspeace National Centers of New England, Inc., in Ellsworth, Maine, was discovered to have employed an excluded speech pathologist. In this case, the individual was not employed directly, but through a contractor. The alleged violation was settled with HHS-OIG on July 31, 2025, with a $44,736.78 financial penalty.
- Brant Jolly, of Fayetteville, Arkansas, has been excluded from participating in federally funded healthcare programs for 10 years for violating the False Claims Act by causing the submission of false claims to Medicare for lab tests that were either never ordered, never rendered, or involved deceased beneficiaries.
- Nirmal Mulye, PhD, based in Miami, Florida, was added to the LEIE by HHS-OIG for defaulting on payment obligations. Dr. Mulye had previously founded a company that was determined to have underpaid Medicaid rebates, then defaulted on his payment obligations under an active settlement agreement. Dr. Mulye will remain on the LEIE until reinstated by HHS-OIG after curing the default.
- Andres Gomes, MD, of Puerto Rico, defaulted on his payments under a False Claims Act settlement agreement with the Department of Justice and HHS-OIG. The settlement agreement resolved allegations that Dr. Gomes did not pay proper remuneration to physicians for patient referrals to clinics for the surgical treatment of peripheral arterial disease. Dr. Gomes will remain on the LEIE until he cures the default.
The post New HHS-OIG Exclusions and Financial Penalties appeared first on The HIPAA Journal.
Florida Considers Rule to Improve Healthcare Data Breach Transparency – The HIPAA Journal
Florida Considers Rule to Improve Healthcare Data Breach Transparency
Healthcare providers in Florida could have new data breach reporting requirements if a recently proposed Florida Administrative Code Regulation Rule is adopted. The rule was proposed by the Agency for Health Care Administration (AHCA) to improve healthcare data breach transparency and preparedness for security incidents. If adopted, healthcare providers will be required to have a contingency plan for information technology incidents, to ensure that critical operations and patient care services can continue during an interruption to normal operations.
The contingency plan must consist of a written policy containing procedures and information regarding the maintenance of critical operations and essential patient care; a procedure for ensuring regular, secure, redundant on-site and off-site data backups (within the continental United States) and verification of the restorability of backed-up data.
An information technology incident is defined as “an observable occurrence or data disruption or loss in an information technology system or network that permits or is caused by unauthorized access of data in electronic form.” The definition covers cyberattacks and insider breaches, including good-faith authorized access by an employee if the data accessed by the employee is used in an unauthorized manner or for an unauthorized purpose.
The new rule will require all covered providers to report an information technology incident to AHCA within 24 hours of the provider determining that an information technology incident has occurred. While not required to be provided in the information technology incident report to AHCA, on request, providers must give AHCA a copy of the police report, incident report, computer forensics report, policies regarding information technology incidents, a list of the information disclosed, the steps taken in response to the incident, and a copy of the contingency plan.
Since healthcare providers are likely also HIPAA-covered entities, these new requirements will be in addition to any requirements under HIPAA. The AHCA will be holding a rule development workshop on September 17, 2025, about the proposed rule.
|
Covered Providers |
||||
| Abortion clinics | Birth centers | Home health agencies | Intermediate care facilities for persons with developmental disabilities | Prescribed pediatric extended care centers |
| Adult day care centers | Companion services or homemaker services providers | Home medical equipment providers | Laboratories authorized to perform testing under the Drug-Free Workplace Act | Residential treatment centers for children and adolescents |
| Adult family-care homes | Crisis stabilization units | Homes for special services | Nurse registries | Residential treatment facilities |
| Ambulatory surgical centers | Health care clinics and | Hospices | Nursing homes | Short-term residential treatment facilities |
| Assisted living facilities | Health care services pools | Hospitals | Organ, tissue, and eye procurement organizations. | Transitional living facilities |
The post Florida Considers Rule to Improve Healthcare Data Breach Transparency appeared first on The HIPAA Journal.